Privacy Policy
Last updated: 30 September 2026
1. Who we are
This website is operated by Calvin Kennedy, a sole trader based in Newcastle, NSW, Australia, trading as calvinkennedy.com. For privacy enquiries, contact hello@calvinkennedy.com.
2. What information we collect
We may collect the following personal information:
- Contact details — name, email address, phone number, and business name when you submit a form on this site or reply to an email from us.
- Business information — your industry, role, and project details when you request a consultation.
- Publicly available business information — business name, email address, phone number, and location sourced from public directories (e.g., Google Business Profile, Yellow Pages, industry association listings) for the purpose of offering relevant business services.
- Usage data — PostHog records pages visited, referral and campaign labels, device type, button interactions and enquiry progress. Submitted names, email addresses and message text are excluded from these analytics events. A random enquiry reference may be recorded so we can connect a confirmed submission to its privately stored enquiry; this makes the data pseudonymous, rather than anonymous. PostHog may also record a masked session replay of how you move through the site, as described in section 11. If you tick the ad-measurement box on an enquiry form, Meta also receives one standard "Lead" event and Google Ads receives one "Enquiry submitted" conversion, as described in section 11.
3. How we collect information
- Directly from you — when you fill in a contact form, subscribe to our newsletter, or email us.
- From public sources — business email addresses and contact details that are conspicuously published on publicly accessible websites, directories, or business listings. We collect business contact details from public directories using structured API queries. We do not use web scraping or email harvesting tools.
- Automatically — usage events and masked session replays via PostHog, with form contents excluded from analytics.
4. Why we collect information
We use your personal information for the following purposes:
- To respond to your enquiries and provide requested services.
- To send you information about services that are directly relevant to your business role (under inferred consent as defined in Schedule 2 of the Spam Act 2003).
- To send newsletters you have subscribed to.
- To improve our website and services.
- To comply with legal obligations.
5. Who we share information with
We do not sell, rent, or trade your personal information. We may share information with:
- Service providers — email delivery (Resend), payment processing (Stripe), hosting (Vercel), analytics (PostHog), advertising measurement (Meta Platforms and Google, only when you tick the ad-measurement box on an enquiry form), and telephony/SMS (Twilio). These providers process data on our behalf and are bound by their own privacy policies.
- Legal requirements — if required by law, regulation, or legal process.
6. How we protect information
We take reasonable steps to protect personal information from misuse, loss, unauthorised access, modification, and disclosure. This includes encrypted storage, access controls, and secure transmission (HTTPS). Credentials are stored in encrypted vaults and are never exposed in code.
8. Cross-border data transfers
Some of our service providers are based in the United States. Under Australian Privacy Principle 8 (APP 8), we are required to inform you when your personal information may be disclosed to overseas recipients. The following sub-processors may receive or process your personal information:
- Twilio Inc (United States) — telephony and SMS delivery. Twilio holds APEC Cross-Border Privacy Rules (CBPR) certification, providing a recognised framework for cross-border data protection.
- Vercel Inc (United States) — website and API hosting. Our application runs on Vercel's serverless infrastructure with data processed in the Sydney region where available.
- Neon Inc (United States) — database hosting. Our database is hosted on Neon's serverless PostgreSQL platform.
We take reasonable steps to ensure that overseas recipients handle your personal information in accordance with the Australian Privacy Principles. This includes selecting providers with strong privacy practices, data processing agreements, and recognised certifications.
9. Your rights
You have the right to:
- Access — request a copy of the personal information we hold about you.
- Correction — request correction of inaccurate or incomplete information.
- Deletion — request deletion of your personal information (subject to legal retention obligations).
- Unsubscribe — opt out of marketing emails at any time by replying "unsubscribe" or using the unsubscribe link in any email. We will honour unsubscribe requests within 5 business days.
- SMS opt-out — reply STOP to any SMS from our missed-call service to immediately stop receiving messages.
To exercise any of these rights, email hello@calvinkennedy.com. We will respond to access and correction requests within 30 days.
10. Data retention
We retain personal information only for as long as necessary for the purpose it was collected. Contact form submissions and enquiry data are retained for up to 24 months after our last interaction. If you unsubscribe from marketing emails, we will delete or de-identify your data within 30 days unless a legal obligation requires us to retain it. Session replays are kept by PostHog for up to 30 days, as described in section 11.
11. Cookies and tracking
This site uses privacy-focused analytics (PostHog) to understand how visitors use our website. PostHog stores a first-party cookie and uses localStorage on your device to maintain a pseudonymous session identifier across page views. This data is used for analytics purposes (e.g., page views, feature usage, session duration). We do not run retargeting ads and do not share PostHog analytics data with advertisers.
Session replay. PostHog may also record how a visitor moves through the site — the page structure, clicks, scrolling and mouse movement — and store it as a replay we can watch to find confusing pages and broken layouts. Every form field is masked before the recording leaves your browser, so text you type is never captured. Text we have marked as sensitive, such as an email address shown back to you on a confirmation page, is masked in the same way. PostHog keeps replays for up to 30 days and then deletes them. Replays use the same first-party cookie and localStorage described above, and are not shared with advertisers.
Advertising measurement (Meta). If you reach this site from a Meta advertisement on Facebook or Instagram and tick the ad-measurement box when you send an enquiry, we load Meta's Pixel script once your enquiry has been recorded and send Meta one standard "Lead" event. That event contains no name, email address, message text or enquiry reference. Meta's script can still receive your IP address, browser and device details, the page address and any Meta cookies already on your device, and Meta processes that data under its own privacy policy. If you leave the box unticked, or your browser sends a Do Not Track or Global Privacy Control signal, Meta's script is not loaded. You can withdraw this choice by leaving the box unticked on a later enquiry or by clearing this site's stored data in your browser.
Advertising measurement (Google). If you reach this site from a Google advertisement, the ad click reference Google adds to the page address is kept in your browser's session storage for that tab. It is not sent anywhere unless you tick the ad-measurement box when you send an enquiry. If you do, we load Google's tag once your enquiry has been recorded and send Google Ads one "Enquiry submitted" conversion with that click reference, so Google can tell the enquiry came from its ad. The conversion contains no name, email address, message text or enquiry reference, and the tag is set not to build advertising audiences from it. Google's tag can still receive your IP address, browser and device details, the page address and any Google cookies already on your device, and Google processes that data under its own privacy policy. The same rules as for Meta apply: leave the box unticked, or send a Do Not Track or Global Privacy Control signal, and Google's tag is not loaded.
Essential cookies may be used for authentication and session management in the client portal.
12. Australian Privacy Act 1988
We handle personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). While the small business exemption may currently apply, we operate as if it does not, in anticipation of its removal.
13. Spam Act 2003 compliance
All commercial electronic messages sent by us comply with the Spam Act 2003 (Cth). Every message includes accurate sender identification, valid contact details, and a functional unsubscribe mechanism. We only contact business email addresses that are conspicuously published and where consent can reasonably be inferred under Schedule 2 of the Act.
14. Complaints
If you believe we have breached the Australian Privacy Principles, you may lodge a complaint by emailing hello@calvinkennedy.com. We will acknowledge your complaint within 7 days and aim to resolve it within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au/privacy/privacy-complaints.
15. Changes to this policy
We may update this privacy policy from time to time. The "last updated" date at the top of this page indicates when the policy was last revised. Continued use of this website after changes constitutes acceptance of the updated policy.
16. Contact
For any privacy-related questions or requests, contact:
Calvin Kennedy
hello@calvinkennedy.com
calvinkennedy.com